Wildcard blacklist entries fail to block DNS queries if the URL includes capital letters. Seems like this would provide an easy way for malicious apps to bypass pi-hole. For example, here's what it I see in my query log:
TraCkeR.example.com Pi-holed (wildcard) /in red font
example.com Pi-holed (wildcard) /in red font
TRacKer.eXaMple.Com OK /in green font
tracker.exampLe.com OK /in green font
I discovered this when one of my kids downloaded a torrent file...